Privacy Policy
Last Updated: August 2026
1. Who Is Responsible for Your Information
This policy is issued under the Protection of Personal Information Act 4 of 2013 (POPIA). It explains what personal information ThabangVision collects, why, who else processes it, how long we keep it, and what you can require of us.
The responsible party is:
THABANGVISION STUDIO (Pty) Ltd
9873 Extension 5, Soshanguve South, Gauteng, 0152, South Africa
Registration number 2025/742948/07
privacy@thabangvision.com
Privacy matters are handled by our Information Officer, reachable at privacy@thabangvision.com.
2. What We Collect
Account and profile. Name, email address, phone number, display name, bio, skills, and avatar photo.
Address and location. Street address, city, province, postal code, and the geographic coordinates of the address you give us. Coordinates are used to match you with nearby crew and equipment.
Identity verification. Photographs of your identity document and a selfie holding it. We also record technical detail extracted from those images, including the date they were taken, device make and model, and any GPS coordinates embedded in them, together with your IP address and browser at the time of submission. We do not ask for or store your ID number as a separate field, but the document image itself contains it.
Banking details, if you receive payouts as a creator: bank name, branch code, account type, account holder name, and the last four digits of your account number. Your full account number is passed straight to our payment provider to set up your payouts and is not kept on our systems.
Bookings and transactions. What you booked, when, for how long, project descriptions, deliverables, amounts paid, and equipment condition records and photographs at collection and return.
Communications. Messages you send through the platform, support requests, contact form submissions, and bug reports, including the device and browser details attached to a bug report.
Conversations with Ubunye, our AI assistant. These are stored on our systems, not only in your browser. See section 6.
Technical and usage data. IP address, browser and device information, pages viewed, and actions taken on the platform. We keep our own record of platform events for product analytics. Where you use Ubunye without signing in, we identify the session by a hashed version of your IP address rather than the address itself.
3. Why We Process It, and On What Basis
To perform our contract with you: creating and managing your account, taking payment, fulfilling bookings, arranging collection and return, settling deposits, and paying creators.
To meet legal obligations: keeping tax and transaction records, and complying with lawful requests.
For our legitimate interests: preventing fraud and identity theft, securing the platform, resolving disputes, and improving the product.
With your consent: identity verification processing, and marketing. Consent for verification is captured explicitly before you upload anything, and recorded with a version and timestamp. You can withdraw consent at any time, though we cannot verify your identity, and therefore cannot let you hire equipment, without it.
4. Identity Verification in Detail
This is the most sensitive information we hold, so we set it out separately.
Where it is stored. Your identity document and selfie are stored in a private, access-controlled storage bucket on our Supabase infrastructure. They are not public, and staff access is through short-lived signed links that expire after five minutes.
Automated checks. To confirm that the person in the selfie is the person on the document, and that the document appears genuine, both images are sent to Google’s AI services for an automated comparison. This means copies of your identity document and selfie are processed by Google, outside South Africa. We do this only for verification, and the result we keep is a match outcome and a confidence score.
Duplicate detection. We store a one-way cryptographic fingerprint of the document file so that the same document cannot be used to verify several accounts. The fingerprint cannot be reversed to recreate the document.
How long we keep it. The document and selfie images are deleted automatically 30 days after your verification has been reviewed. The technical detail described in section 2, the document fingerprint, and the outcome of the review are kept for longer, for fraud prevention and to show that we verified you properly. Your verification status and consent record are kept for the life of your account plus five years for tax and legal audit purposes.
5. Who Else Processes Your Information
We use the following operators. Each processes only what it needs to, under our instruction.
- Supabase — database, authentication, and file storage. Holds effectively everything described above.
- Paystack — payments and creator payouts. Receives your email address and transaction detail, and for payouts, the account holder name, bank account number, and branch code.
- PayFast — an alternative payment provider we keep available. Not currently active.
- Cloudinary — image hosting for avatars, portfolios, and listing photographs. Verification documents are not stored here.
- Google — AI services used for the verification checks in section 4, for lower-cost assistant responses, and for search indexing of platform content.
- Anthropic — the AI model behind Ubunye. Receives your messages and, when you are signed in, relevant context from your profile and bookings.
- Vercel — hosting, plus page-view and performance analytics.
- Google Workspace (Gmail) — outbound email. Receives recipient addresses and message contents.
- Twilio — WhatsApp messaging, where you contact us on that channel.
- OpenStreetMap — address lookup. When you type an address into our address field, that text is sent from your browser to OpenStreetMap’s servers to suggest matches.
We do not sell your personal information, and we do not share it for anyone else’s marketing.
6. Ubunye AI Conversations
Your conversations with Ubunye are stored in our database against your account, or against a hashed session identifier if you are not signed in. Authorised administrators can review them for support, safety, and quality purposes.
Message content is sent to our AI providers to generate a response. Please do not paste identity numbers, banking details, passwords, or other sensitive information into the assistant.
7. Cross-Border Transfers
Several of the operators above process personal information outside South Africa. Where that happens we rely on section 72 of POPIA: the recipient is bound by an agreement or by laws that provide a comparable level of protection to POPIA, or the transfer is necessary to perform our contract with you.
The transfer that matters most to you is the one described in section 4: your identity document and selfie are processed by Google outside South Africa as part of verification.
8. How Long We Keep Things
- Identity document and selfie images — deleted 30 days after review.
- Verification outcome, technical detail, and document fingerprint — retained for fraud prevention.
- Consent records and verification status — account life plus 5 years.
- Transaction and booking records — 5 years, as tax law requires.
- Banking details (bank, account holder, last four digits, payout reference) — until you remove them or your account is closed.
- Profile and account data — deleted within 30 days of account closure, except where we must keep a record.
- Ubunye conversations and platform event logs — retained while they remain useful for support, safety, and product analytics.
9. Security
Access to the database is controlled by row-level security rules so that, as a rule, you can read only your own records. Verification documents sit in a private bucket reached only through expiring signed links. Transport is encrypted. Sessions log out automatically after 30 minutes of inactivity. We keep an audit trail of administrative actions.
We do not store full bank account numbers. When you add banking details, the number goes directly to our payment provider, which returns a reference we use to pay you. We keep only the last four digits, so you can recognise the account. Even so, access to that record is restricted at the database level to the account that owns it.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the Information Regulator as POPIA requires.
10. Cookies and Analytics
We use essential cookies for sign-in and session management. Without them the platform cannot keep you logged in.
We also use analytics that record page views, performance, and how the platform is used. We do not currently show a cookie consent banner, and we do not use advertising or cross-site tracking cookies. You can block or remove cookies in your browser settings, though sign-in will stop working if you block the essential ones.
11. Marketing
We send transactional messages — booking confirmations, verification outcomes, deposit and dispute notices — because they are necessary to perform our contract with you. These are not marketing and you cannot opt out of them while you hold an active booking.
Marketing emails are sent only if you have opted in, and opting in is always a separate, unticked choice. To stop receiving them, email privacy@thabangvision.com and we will remove you.
12. Your Rights
Under POPIA you may:
- ask what personal information we hold about you, and get a copy;
- ask us to correct or complete anything inaccurate;
- ask us to delete information we no longer have a lawful reason to keep;
- object to processing based on our legitimate interests;
- withdraw a consent you previously gave;
- complain to the Information Regulator.
To exercise any of these, email privacy@thabangvision.com from the address on your account. There is currently no self-service delete button in the dashboard, so account deletion is handled by us on request. We respond within 30 days, and we may need to confirm your identity first.
Some information we must keep even after you ask us to delete it, in particular transaction records required by tax law. We will tell you what we are keeping and why.
13. Children
The platform is for people aged 18 and over, and you confirm your age during verification. We do not knowingly collect information about children. If you believe a child has given us personal information, contact us and we will delete it.
14. Complaints
Raise a privacy concern with us first at privacy@thabangvision.com. We acknowledge within 2 business days and aim to resolve within 10.
If you are not satisfied, you may complain to the Information Regulator (South Africa):
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints POPIAComplaints@inforegulator.org.za
General inforeg@inforegulator.org.za
https://inforegulator.org.za
15. Changes to This Policy
We update this policy when our practices change. The current version is always on this page, with the date at the top. Where a change materially affects your rights, we will tell you directly.
See also our Terms of Service and Refunds, Returns and Cancellations Policy.